← Back to results

Join Forward Networks as a GRC Engineer to automate compliance and security operations in a dynamic environment.

Location
Santa Clara, CA
Compensation
$140k–$170k/yr
Level
mid
Type
full time

Posted by employer 5 days ago

First seen on Joblaze 4 days ago

Last verified on the company career page 12 hours ago

Apply at Forward Networks → Save job Scanned from forwardnetworks.com

What you'll build

  • Write and maintain security policies and procedures
  • Build control tests for automated compliance
  • Manage and extend GRC platform using scripts
  • Lead SOC 2 Type II audits
  • Participate in security alert triage

Must have

  • 3+ years in GRC, compliance, security engineering, or IT audit
  • Experience writing policies and procedures
  • Experience with GRC/compliance automation platforms
  • Basic scripting knowledge in Python or Bash, SQL
  • Some exposure to SIEM/SOAR tooling

Nice to have

  • Comfort with Linux administration and scripting
  • Certifications like Security+, CISA, CISSP
  • Experience tuning or migrating a SIEM/SOAR setup
  • Understanding of tabletop exercises
  • Experience with endpoint compliance in a Mac-centric environment

AI in the day-to-day

You will be able to take advantage of AI to assist in your tasks.

Requirements

Experience
3+ years

Not disclosed in this posting: work arrangement, visa sponsorship.

Joblaze summary

The GRC Engineer at Forward Networks focuses on automating compliance processes and managing audits, utilizing scripts and API integrations to streamline evidence collection and control monitoring. Key skills include experience with compliance frameworks like SOC 2 and ISO 27001, along with basic scripting abilities in Python or SQL. This role is suited for someone with at least three years in GRC or security engineering, who is comfortable navigating both technical and compliance landscapes. The position also offers opportunities to engage in Security Operations, expanding the engineer's responsibilities over time.

Joblaze insights

  • Listed 4 days ago — first seen on Joblaze September 27, 2026. Last confirmed on Forward Networks's careers page October 1, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 58% of 52 comparable mid security roles in United States that list Python we track (median $130,000 across 21 companies). See Python salary trends
  • Python appears in 43.8% of 194 comparable mid security roles in United States; Drata appears in 1% of 194 comparable mid security roles in United States.

Quick facts

What's the salary range?
Forward Networks lists $140,000–$170,000 for this role.
How much experience is required?
At least 3 years of relevant experience for this GRC Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: Drata, ISO 27001, ISO 42001, Python, SIEM, SOAR.
What seniority level is this role?
Forward Networks targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this GRC Engineer role at Forward Networks.

From the original posting

Forward is looking for a GRC Engineer. GRC Engineering is a new discipline: instead of chasing down screenshots every quarter and hoping the auditor doesn't ask too many follow-up questions, you're building scripts and API integrations that pull evidence straight from the source systems and keep it current on their own. If you've spent any time reading about the field, you've probably run into grc.engineering, the GRC Engineering Club, or grcengineer.com. We'd rather hire someone who already thinks this way than someone who needs to be convinced of it; if your engineering skills enable doing more than a traditional GRC Analyst role, you're the right fit.

Your initial focus, likely for the next 6 months, is GRC Engineering: compliance automation, audit management (SOC 2, ISO 27001/42001), control design and testing, and risk management.

Once the most critical automations are in place, this job broadens to include a Security Operations piece: mostly SIEM and SOAR work plus whatever incident response comes up. This is your chance to go beyond mere exposure to SecOps work, to directly participate in alert triage, SIEM/SOAR administration and tuning, enforcement work, and incident response. This is a real split, and we're looking for someone who can grow to handle both types of work.

What You'll Do

GRC Engineering (main focus of role)

  • Policy & Documentation: Write, maintain, and actively drive review cycles for security policies and procedures.
  • Automated Control Testing: Build control tests that verify real system configurations directly at the source, rather than manual spreadsheets. If a control says MFA is enforced, you should be able to verify that in the identity provider yourself.
  • Manage and extend our GRC platform (Vanta, Drata, etc.) using scripts and API integrations.
  • Control Monitoring: Continuously manage control drift between audits and drive remediation to completion.
  • Audit Management: Lead day-to-day SOC 2 Type II audits and lay groundwork for ISO 27001 and ISO 42001.
  • Risk Management: Maintain a prioritized risk register and run actionable risk assessments.
  • Handle vendor security reviews and due diligence: pull evidence from a vendor's API or trust page, rather than mailing them a 40-question spreadsheet.
  • Engineering Collaboration: Integrate compliance requirements directly into engineering workflows, such as CI/CD, access provisioning, and change management.

Security Operations (additional piece after critical automations in place)

  • SIEM & SOAR Admin: Tune detection rules, correlation logic, and response playbooks.
  • Endpoint Support: assist with EDR, DLP, and endpoint break/fix and incident response cases.
  • Alert Triage: Participate in security alert triage and documentation.
  • Jump into incident response when something happens: investigation, helping contain it, and post-mortem write-ups.
  • Feed what you see in the SOC back into the GRC side of your job. If operations tell a different story than what the compliance platform says, that gap is worth knowing about.

What We're Looking For

Required

  • 3+ years in GRC, compliance, security engineering, IT audit, or equivalent, with on-the-job exposure to control design, risk assessment, AND compliance frameworks.
  • Experience writing policies and procedures, with a focus on testable and verifiable outcomes.
  • Time spent doing real work in a GRC/compliance automation platform (Vanta, Drata, Thoropass, Anecdotes, or similar).
  • Solid working knowledge of SOC 2. ISO 27001 experience is a plus. ISO 42001 is a possible future endeavor, but curiosity about AI governance is important.
  • Basic scripting knowledge: Python or Bash, SQL, and comfortable pulling data from an API, parsing a log file, or automating something you used to do by hand. This is not a software engineer role and you will be able to take advantage of AI to assist, but the ability to read, troubleshoot, and deliver working scripts is a requirement.
  • Some exposure to SIEM/SOAR tooling (Splunk, Chronicle, Panther, XSOAR, Tines, whatever you've used) and a basic feel for how incident response actually runs.
  • The ability to speak to an auditor and an engineer in languages they understand, as both the GRC and engineering skill sets will be utilized.
  • A tolerance for ambiguity. "GRC Engineer" is an evolving field/role. We will be figuring out parts of this role as time goes on together.
  • Experience with endpoint compliance in a Mac-centric environment.

Nice to Have

  • We run in the cloud but also still operate our own data center, so comfort with straight Linux administration and scripting matters just as much as anything cloud-native. If you've worked with Terraform or policy-as-code, that helps too.
  • Certs like Security+, CISA, CISSP, or ISO 27001 Lead Implementer/Auditor are fine to have. We just care more about whether you can trace a control back to the system it's actually describing.
  • Time spent tuning or migrating a SIEM/SOAR setup, or running incident response for real, not just in a tabletop exercise.
  • Understanding tabletop exercises, how to run them, how to conduct a post-mortem and how to drive the findings to completion with stakeholders.

The base pay range for this role is between $140,000 and $170,000. This range represents the low and high end of the salary for this position. Actual compensation will vary based on factors including location, candidate experience, skills, and level.

Standard company text repeated across Forward Networks's postings is omitted here.

Similar positions

Cursor
Security GRC Engineer
Cursor · San Francisco
HappyRobot
GRC Compliance Specialist
HappyRobot · Spain
Fireworks AI
Senior GRC Specialist
Fireworks AI · San Mateo
Profound
Member of Technical Staff, GRC Director
Profound · New York, New York
OpenRouter
GRC Manager
OpenRouter · Remote (US)